Splunk Search

Alert Based Off Current Event Duration

NewToSplunk1
Explorer

Goal: Being able to alert off the latest event if the event is more than 300 seconds and is not blank or "non-productive".

Here is my current search and the results: 

NewToSplunk1_0-1694011225839.pngNewToSplunk1_0-1694011225839.png

NewToSplunk1_2-1694012082568.pngNewToSplunk1_2-1694012082568.png

Every incident is an open or a closing of an event. If the incident is blank, that signifies a closing of the previous event. If the incident has a string, that is the current open event. 

In my ideal scenario, I would alert based on any incident where I have a string value within the incident field, current duration has surpassed 300 seconds, and I don't have a value in the total duration field. 

However, when I try to add a filter for | where total duration = "", no results are returned at all.. Which I am confused about since the latest totalduration event is blank since streamstats is false...

Any help or tips greatly appreciated!

Labels (2)
0 Karma
1 Solution

ITWhisperer
SplunkTrust
SplunkTrust

Try this

| where isnull(TotalDuration)

View solution in original post

NewToSplunk1
Explorer

Thank you!!

0 Karma

NewToSplunk1
Explorer

| where TotalDuration = null returns no results as well.

0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Try this

| where isnull(TotalDuration)
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...